Service 03
Migration-Roadmap Generation
Answer a couple of questions and get a phased PQC migration plan, sequenced against NIST's finalized standards and the 2035 federal migration deadline.
Organization size
Priority systems
Phase 1Discover (0-3 months)
- •Build a cryptographic inventory: algorithms, key sizes, certificate authorities, libraries, and where each is used.
- •Classify data by confidentiality horizon to flag 'harvest now, decrypt later' exposure.
- •Identify systems and vendors on your critical path, and request their PQC support timelines.
Phase 2Prioritize (2-4 months)
- •Rank systems by risk: long-lived secrets and public-facing key exchange first.
- •Assign owners and budget for the highest-priority items identified in Phase 1.
- •Confirm your CA's roadmap for issuing ML-DSA / hybrid certificates.
Phase 3Pilot (3-6 months)
- •Stand up a hybrid ECDH + ML-KEM (FIPS 203) key-exchange pilot on a non-critical service.
- •Validate performance impact: handshake latency, message size, CPU overhead.
Phase 4Roll out (6-18 months)
- •Migrate prioritized systems in waves, favoring cryptographic agility so future algorithm swaps don't require re-architecture.
- •Track progress against FIPS 203/204/205 conformance and internal milestones.
Phase 5Verify & sustain (ongoing)
- •Validate implementations against NIST CAVP/CMVP where applicable.
- •Re-run the cryptographic inventory quarterly; treat crypto agility as a standing engineering requirement, not a one-time project.
- •Track NIST updates: FN-DSA (Falcon) finalization, HQC (FIPS pending), and additional signature on-ramp candidates.